Back to Feed
Nation-stateOct 2, 2026

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

China-based Warlock group targets critical infrastructure using SharePoint vulnerabilities.

Summary

The China-based Warlock group, linked to Longlegs and Storm-2603, continues to exploit SharePoint vulnerabilities, including ToolShell and newer flaws like CVE-2026-32201, to target critical infrastructure, government, and education entities. Attacks involve deploying ransomware, disabling security software, and using sophisticated techniques like DLL sideloading and abusing Visual Studio Code tunnels for covert access.

Full text

The Warlock ransomware group continues to target SharePoint servers in attacks against critical infrastructure, government, and education entities, Symantec reports. Warlock is believed to be operated by a China-based hacking group tracked as Longlegs and Storm-2603, which has been linked to malicious operations such as CL-CRI-1040, CamoFei, and ChamelGang. Last year, the Chinese state-sponsored groups Linen Typhoon and Violet Typhoon were seen exploiting two SharePoint vulnerabilities dubbed ToolShell as zero-days at least two weeks before public disclosure. Within weeks, more than 400 SharePoint servers were compromised, and Storm-2603’s exploitation of ToolShell stood out amid heavy APT activity. By October 2025, researchers uncovered numerous Warlock ransomware attacks that exploited ToolShell. Some of the group’s victims included a Middle East telecom firm, African and South American government entities, and a US university. According to a fresh Symantec report, Storm-2603 continues to favor the exploitation of SharePoint bugs in attacks. In addition to ToolShell, its arsenal may also include recent flaws such as CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, CVE-2026-58644, CVE-2026-50522, and CVE-2026-55040.Advertisement. Scroll to continue reading. Over the past two months, the Warlock operator has hit at least four victim organizations in Portuguese- and Spanish-speaking countries. “The victims included two critical infrastructure operators, a water utility and a telecommunications provider, along with a regional government body and a university,” Symantec reports. As part of one intrusion, the hacking group deployed a tool to disable the security software on at least 40 systems and then executed Warlock on at least 33 of them. The group’s exploitation of SharePoint flaws is typically followed by webshell deployment, ASP.NET machine key exfiltration, and the deployment of a forced signed payload for remote code execution (RCE). Storm-2603 relies on DLL sideloading for in-memory code execution, drops additional payloads from legitimate file-sharing and storage services and a vulnerable driver to disable security tools, and relies on living-off-the-land tools for reconnaissance and command execution. “The group has also been observed abusing Visual Studio Code’s built-in tunnel feature, installing the code-insiders.exe binary as a service to establish covert remote network access that blends into traffic that typically originates from developer or administrator workstations,” Symantec notes. Additionally, the threat actor stages the Warlock payload inside the domain’s SYSVOL share, which is automatically replicated to every domain controller and is readable domain-wide, to execute the file-encrypting ransomware at scale. “Longlegs’ continued activity, more than a year after Warlock ransomware first came to prominence, shows that exploitation of ToolShell and other related SharePoint vulnerabilities remains a viable initial access route for attackers on SharePoint deployments that have not been patched or otherwise mitigated,” Symantec notes. Related: Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks Related: Hackers Use ChatGPT Custom GPTs in ClickFix Attacks Related: Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft Related: SmarterTools Hit by Ransomware via Vulnerability in Its Own Product Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Zimbra Vulnerability Exploited in the Wild Prior to Public DisclosureZammad Zero-Days Exploited in AI-Powered DIVD Hack500,000 Active Credentials Left Exposed on GitHubCisco Patches Exploited Catalyst SD-WAN Zero-Day VulnerabilityWatchGuard Patches Critical Fireware OS Code Injection VulnerabilityChrome, Firefox Updates Patch Over 100 VulnerabilitiesRussian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent AttacksShinyHunters Defiant After FBI Calls on Members to Come Forward Latest News AI Agents Aimed SQL Injection at US and Canadian Government SitesExploited Fortinet FortiMail Zero-Day Calls for Urgent ActionZero Trust Creator Says Model Holds Firm Against AI-Assisted AttacksOsavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical DomainsEnterprises Struggle to Prepare for AI and Quantum Threats, PwC SaysHacker Conversations: Rob Juncker, a Knock at the Door and a Moral CompassPolice Shut Down KillSec Ransomware, Identify Alleged Teen LeaderAI Has Changed Attack Speed, Not Security Fundamentals Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Securing AI Agents, MCPs, and AI Automations October 7, 2026 Learn how to address potential risks and not restrict AI adoption in your organization. See what a centralized AI gateway is and how it works in practice. Register Virtual Event: Zero Trust & Identity Strategies Summit 2026 October 14, 2026 Join as we decipher the world of zero trust and share war stories on securing an organization by eliminating implicit trust and continuously validating every stage of a digital interaction. Register People on the MoveLumen Technologies has named Kim Keever as CSO.Quantum Secure Encryption Corp. has appointed Joseph Hall as CIO.David Cass has joined Grayscale Investments as Chief Risk Officer.More People On The MoveExpert Insights AI Has Changed Attack Speed, Not Security Fundamentals As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. (Joshua Goldfarb) Four Cyber Threats Harboring Big Plans for the Future - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. (Steve Durbin) Begin at the End: How to Enable Agentic Remediation Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. (Nadir Izrael) “We Think the Security Control Is Working” Is No Longer Good Enough Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. (Sravish Sridhar) This Key Will Self-Destruct: An Open Standard for Revocable API Keys Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. (Matt Honea) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-32201
  • cve — CVE-2026-45659
  • cve — CVE-2026-56164
  • cve — CVE-2026-58644
  • cve — CVE-2026-50522
  • cve — CVE-2026-55040

Entities

Warlock (threat_actor)Longlegs (threat_actor)Storm-2603 (threat_actor)Linen Typhoon (threat_actor)Violet Typhoon (threat_actor)SharePoint (product)